Bluetooth Broken? Apache NimBLE Flaws Enable Spoofing & Eavesdropping
ID: d4e77d3f-8d76-56cb-abfe-d010ee5fe415
STIX ID: report--d4e77d3f-8d76-56cb-abfe-d010ee5fe415
Feed Name: securityonline.info
Threat Score
Apache NimBLE (Bluetooth 5.4 stack) versions up to 1.8.0 contain four disclosed vulnerabilities—two Important flaws (CVE-2025-62235 authentication-bypass via spoofed re-bonding and CVE-2025-52435 pause-encryption handling leading to silent downgrade/eavesdropping) and two Low-severity memory/stability issues—patched in NimBLE 1.9.0; vendors and developers are urged to apply the update to mitigate proximity-based attacks on IoT and embedded devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
